CVE-2023-24055
Last modified
CVE-2023-24055 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.. EPSS estimates a 3.66% chance of exploitation in the next 30 days.
Description
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Keepass | Keepass | <= 2.53 |
References
- https://sourceforge.net/p/keepass/discussion/329220/thread/a146e5cf6b/Patch, Third Party Advisory
- https://sourceforge.net/p/keepass/feature-requests/2773/Third Party Advisory
- https://sourceforge.net/p/keepass/discussion/329220/thread/a146e5cf6b/Patch, Third Party Advisory
- https://sourceforge.net/p/keepass/feature-requests/2773/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-24055?
How severe is CVE-2023-24055?
How do I fix CVE-2023-24055?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-24049An issue was discovered on Connectize AC21000 G6 641.139.1.1…9.8
- CVE-2023-2405The CRM and Lead Management by vcita plugin for WordPress is…6.5
- CVE-2023-24050Cross Site Scripting (XSS) vulnerability in Connectize AC210…5.4
- CVE-2023-24051A client side rate limit issue discovered in Connectize AC21…9.8
- CVE-2023-24052An issue discovered in Connectize AC21000 G6 641.139.1.1256 …9.8
- CVE-2023-24054Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2023-24056In pkgconf through 1.9.3, variable duplication can cause unb…5.5
- CVE-2023-24057HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow…8.1
- CVE-2023-24058Booked Scheduler 2.5.5 allows authenticated users to create …4.3
- CVE-2023-24059Grand Theft Auto V for PC allows attackers to achieve partia…7.3
- CVE-2023-2406The Event Registration Calendar By vcita plugin, versions up…5.4
- CVE-2023-24060Haven 5d15944 allows Server-Side Request Forgery (SSRF) via …5
Are you affected by CVE-2023-24055?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
